Scope and contact
KPIAds is currently a private beta. KPIAds acts as controller for the account, website, support, and billing data described here. The final legal entity name, registered address, and governing jurisdiction must be inserted before registration opens to the general public.
Privacy and data-rights requests can be sent to support@kpiads.app.
Data we process
- Account and organization: name, email, password hash, verification state, membership, role, and account status.
- Project configuration: project names, store domains, currencies, timezones, property assignments, and selected campaigns.
- Store reporting: daily aggregated revenue, refunds, order counts, currency, and connector health. The base reporting flow does not send customer names, emails, addresses, payment data, line items, or raw orders to KPIAds Core API.
- Advertising reporting: connected account and property identifiers, campaign names and classifications, spend, impressions, clicks, conversions, and provider-attributed values returned by authorized advertising APIs.
- Authentication and secrets: OAuth tokens and scoped connector credentials required to keep authorized connections working. Secrets are not shown in the product UI.
- Billing: plan, subscription state, resource usage, and payment-provider identifiers. KPIAds does not store full card details.
- Operations: IP address and request metadata where required for security, correlation IDs, synchronization state, errors, audit events, and product usage events.
Purpose and legal basis
KPIAds uses this data to create and secure accounts, connect authorized services, generate reports, enforce plan limits, provide support, prevent abuse, maintain auditability, and meet legal obligations.
Depending on the processing context, the basis is performance of the service agreement, legitimate interests in operating and securing the service, compliance with law, or consent where it is specifically requested. Authorizing a third-party integration can be revoked from that provider and from KPIAds.
Retention and deletion
Reporting retention follows the active plan: 30 days on Free, 90 days on Starter, 180 days on Agency, and a configured period on Custom. Security, audit, support, and billing records may use different retention windows when needed for integrity or legal obligations.
Disconnecting a store or advertising provider stops future synchronization and revokes or removes the relevant credentials where supported. Uninstalling a connector does not automatically delete data already synchronized to the KPIAds account. Account or data-deletion requests can be sent to support.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may also withdraw consent where processing relies on consent and lodge a complaint with the competent data protection authority.
KPIAds may ask for information needed to verify the request and protect the account. Requests should receive a response without undue delay and within the period required by applicable law.
Security and cookies
KPIAds uses access controls, tenant isolation, scoped credentials, encryption for stored secrets, transport encryption, audit logging, and security testing. No internet service can guarantee absolute security.
The beta website uses essential cookies for authentication, CSRF protection, and session security. Non-essential advertising cookies are not part of the current beta. This notice and any consent controls will be updated before such technologies are introduced.